The real test of AI governance isn't in Brussels; it's in the world's small island states

Global AI rules assume state capacities that most nations do not have. A framework now in the ITU's official record shows why the hardest cases hold the answers for everyone.

Sovereignty is about optionality: the agency to switch providers, hedge dependencies, and adapt as the technology shifts. Image: Canva

A year ago, digital sovereignty meant owning the stack: the compute, the models, the data.

 

Today, the sharper view is that sovereignty is about optionality: the agency to switch providers, hedge dependencies, and adapt as the technology shifts.

 

That is a genuine advance. It also rests on a quiet assumption that collapses in contact with most of the world.

 

It assumes you have options.

 
Former Chief Information Officer at the Maldives' National Centre for Information Technology and later as Minister of State responsible for technology, Mohamed Shareef.

For a small state buying a national digital identity system, there may be two credible vendors, not 20. The contract is a rounding error to a global supplier.

 

The data already sits in a foreign cloud that cannot be moved without breaking a service millions of citizens depend on.

 

In those conditions, “keep your options open” is not a strategy. It is a description of a door already closing.

 

I spent a career inside this problem, as Chief Information Officer at the Maldives' National Centre for Information Technology and later as Minister of State responsible for technology.

 

I have set out what is actually happening in a framework called the Amplified Sovereignty Paradox.

 

The paper was presented at ITU Kaleidoscope 2026 in Geneva and is published in the ITU's record; you can read it in full here. This is the short version.

The paradox becomes a trilemma

 

For years, sovereignty has been a two-way tension. The infrastructure that empowers citizens is the same infrastructure that can surveil them.

 

Artificial intelligence (AI) adds a third axis. Three kinds of sovereignty now collide in every major deployment.

 

Individual sovereignty is the citizen's ability to understand and contest an automated decision.

 

National sovereignty is the state's ability to set its own digital policy without being captured by a foreign vendor. Technical sovereignty is the ability to audit, verify, and modify the systems running inside your own borders.

 

You cannot have all three at once.

 

Picture the specification every small state wishes it could write.

 

Provide a biometric identity system that gives every citizen seamless access, creates no surveillance capacity, uses algorithms we can fully audit, and costs under half a million dollars.

 

No vendor on earth can deliver that document, and officials know it even before the tender is drafted.

 

AI tightens the trap in two ways.

 

Surveillance automation turns a dormant capacity into an always-on governance layer whose speed outruns any three-person regulator.

 

And structural vendor dependence sends critical functions to proprietary systems that cannot be moved on-premise, with data offshoring and residency laws quietly ignored to keep the lights on.

 

The state keeps the legal right to govern, but loses the material capacity to so.

Why the smallest states are the biggest warning

 

The instinct is to file small island developing states under “special case.” That instinct is backwards.

 

These nations cannot afford latent trade-offs.

 

Geographic fragmentation forces them to become digital-first, because you cannot run a service counter on every one of the 1,190 islands (Maldives).

 

Climate vulnerability raises the stakes: when a minister must choose between a foreign vendor's proprietary cyclone-prediction model and no early-warning system at all, transparency principles give way to arithmetic about survival.

 

And capacity is thin by design, with data protection authorities running on one to five technical staff against Europe's hundreds.

 

A large economy papers over its dependencies with scale and budget.

 

A small state has to make the choice out loud, and now. That is exactly why these countries are early-warning systems for everyone else. The dependencies they hit first are the ones larger states hit later.

From critique to specifications

 

Diagnosis without a remedy is just pessimism. The paper turns the paradox into five requirements in standards language, each mapped to a specific ITU-T Study Group for the 2027 to 2029 cycle.

 
  1. Decision transparency. Automated eligibility systems must keep tamper-evident logs and let citizens see how their data was used.
  2. Human redress. Every automated decision must carry an explanation and a human reviewer with real authority to overturn it.
  3. Model change notice. Model changes that shift who qualifies must be disclosed in advance, with fairness testing.
  4. Data residency and escrow. Citizen data stays in-jurisdiction; model artefacts sit in escrow with defined release conditions.
  5. Procurement transparency. Vendors supply a machine-readable bill of materials showing training-data sources, sub-processors, and jurisdictions.
 

The design has graduated. A government meets the baseline with what it has today and climbs as capacity grows.

 

Two of the five points ships now as lightweight overlays with open-source reference code, so a regulator with three staff is not asked to build from nothing.

 

These standards do not dissolve the trilemma. They run into a human-capital cliff, the physics of diesel-powered energy costs, and contracts too small to give regulators real leverage.

The exit is regional, not national

 

No island nation of a few hundred thousand people will ever audit a frontier model alone.

 

The realistic path is shared capacity: regional technical bodies, pooled sovereignty stacks, and collective bargaining through the Caribbean Community (CARICOM), the Pacific Islands Forum, and the Indian Ocean Commission.

 

It is the same logic I have argued for Asia's open-source coalition. Sovereignty in the AI age is a collective achievement, not an individual possession.

 

Solutions engineered for the hardest constraints tend to work everywhere. Solutions engineered for abundance work only where there is abundance.

 

The unseen frontier of AI governance is not in Silicon Valley, Brussels, or Beijing. It is in Bridgetown, Malé, and Kingston. The rest of the world would do well to watch what gets built there.

 

----------------------------------

 

Mohamed Shareef is a former Minister of State for Environment, Climate Change and Technology in the Maldives (2021-2023). He previously served as Permanent Secretary of Science and Technology Ministry (2019-2021) and the Chief Information Officer at the National Centre for Information Technology (2009-2014) and led the development of the country's national digital public infrastructure. He also served in the academia including as a researcher at the United Nations University. He currently serves as Senior Advisor for Digital Transformation at Nexia Maldives. His paper, “The Amplified Sovereignty Paradox: AI Governance Lessons from Small Island Developing States,” received the First Prize Best Paper Award at ITU Kaleidoscope 2026 and is published by the ITU at http://handle.itu.int/11.1002/pub/829d0172-en.